Data processing agreement
For the KSPR Checkout plugin. It applies between you as the operator of a website that uses the plugin (controller) and Lulu Amani by Kasper (processor), and is part of the plugin terms. It follows Art. 28 of the EU GDPR and Art. 9 of the Swiss Federal Act on Data Protection (FADP).
1. Subject and duration
We run the checkout service for your website: we register your site, connect your Stripe account, sync your products to Stripe, create Stripe Checkout sessions from the cart of your visitors and return the session result to your thanks page. The agreement runs as long as you use the plugin and ends with the last website you cancel.
2. Data and data subjects
- Data subjects: visitors and customers of your shop.
- Data: cart contents (Stripe price IDs and quantities), checkout session IDs, the origin website, and the session result read from Stripe for your thanks page (for example name, email address, items and payment status), plus the consent to your terms if you turned that on.
- We do not store your customers' data on our server. It is passed on to Stripe or read from Stripe for the request and not kept. Our server stores only the data about your website (site ID, domains, a hash of the site secret, the connected Stripe account ID and the subscription status). Payment data is collected by Stripe directly and never reaches us.
Your own data as our customer (for example your subscription and invoices) is not covered here; for that we are the controller, see the privacy notice.
3. Instructions
We process the data only to provide the checkout service as described in the plugin terms and as set in the plugin, which together are your documented instructions. If we think an instruction breaks data protection law, we tell you.
4. Confidentiality and security
Only the owner of Lulu Amani by Kasper has access to the service, bound to confidentiality. Measures: encrypted connections (TLS) only; server in Germany with access limited to SSH keys; site secrets stored only as hashes; Stripe keys never in the browser or the published site; prices are always read from Stripe; data minimisation as described above; regular updates of the server software.
5. Subprocessors
We use Hetzner Online GmbH, Germany, as the host of our server. Stripe is not our subprocessor: Stripe processes the payment under your own contract with Stripe, in your own Stripe account. We tell you about a new subprocessor at least 30 days in advance by email; if you object, you can cancel the plugin with a pro rata refund.
6. Support for you
We help you, as far as we can, to answer requests from data subjects, with data protection impact assessments and with your duty to report breaches. We tell you without undue delay if we become aware of a personal data breach that concerns your website.
7. End of processing
When you cancel the last website, we delete its site entry within 30 days, unless the law requires us to keep it. Data in your Stripe account stays with you.
8. Information and audits
We give you the information you need to show that this agreement is kept. Audits are possible after reasonable notice and at your cost; a written answer to your questions comes first.
9. Location and law
We are based in Switzerland, which the EU recognises as providing adequate data protection; the server is in Germany. Swiss law applies. If this agreement and the plugin terms contradict each other on data protection, this agreement takes precedence.
Version of 3 October 2026